首页    期刊浏览 2024年07月06日 星期六
登录注册

文章基本信息

  • 标题:Detecting Anomalies in Active Insider Stepping Stone Attacks
  • 本地全文:下载
  • 作者:Giovanni Di Crescenzo ; Abhrajit Ghosh ; Abhinay Kampasi
  • 期刊名称:Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications
  • 印刷版ISSN:2093-5374
  • 电子版ISSN:2093-5382
  • 出版年度:2011
  • 卷号:2
  • 期号:1
  • 页码:103-120
  • 出版社:Innovative Information Science & Technology Research Group
  • 摘要:Network attackers frequently use a chain of compromised intermediate nodes to attack a target machine and maintain anonymity. This chain of nodes between the attacker and the target is called a stepping stone chain. Various classes of algorithms have been proposed to detect stepping stones, timing correlation based algorithms being a recent one that is attracting significant research interest. However, the existing timing based algorithms are susceptible to failure if the attacker actively tries to evade detection using jitter or chaff. We have developed three anomaly detection algorithms to detect the presence of jitter and chaff in interactive connections, based on response time, edit distance and causality. Experiments performed on Deter using real-world traces and live traffic demonstrate that the algorithms perform well with very low false positives and false negatives and have a high success percentage of about 99%. These algorithms based on response times from the server and causality of traffic in both directions of an interactive connection have made the existing stepping stone detection framework more robust and resistant to evasion
国家哲学社会科学文献中心版权所有